URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: naftir.sbs
Domain registrar:Hostinger -
Domain registration date:2025-11-26 21:07:35 UTC
Abuse complaint sent to registrar: Yes (2025-11-27 09:53:01 UTC to domains{at}hostinger[dot]com)
Domain registry:Special Broadcasting Service -
Abuse complaint sent to registry: Yes (2025-11-27 09:53:02 UTC to ngtld-sbs{at}cscinfo[dot]com)
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Blocked
Firstseen:2025-11-27 09:47:09 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-27 16:12:50 194.36.191.196hosting1.nl.hostsailor.comNot listedAS60117 HS- NLno
2025-11-27 09:47:16 5.10.248.240ircp1.my-servers.usNot listedAS212607 POTENTING-AS- IRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-11-27 09:47:16https://naftir.sbs/naftkhodm.zipOffline juroots

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-11-27 09:47:1679485989ae3955e10e7fcdc9deeb33edae0966067e1f4748dcea3a98653e85d1zip